bybit-trading

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the trading purpose aligns with Bybit API access and credential use, and data flows stay mostly within official Bybit/GitHub-owned infrastructure. However, the skill has elevated risk because it self-updates from remote mutable content, lazy-fetches code/modules, and authorizes autonomous high-impact financial actions; this is coherent with purpose but not low-risk.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Aug 12, 2026, 05:20 PM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fbybit-trading%2F@11726d6df75735943287a6881cffe08d1c6c7f41cd7117b06e0f770da376ff06
Security Audit — socket — bybit-trading